PT-2023-14065 · Mailenable · Mailenable

Georget

·

Published

2023-01-13

·

Updated

2023-01-23

·

CVE-2022-42136

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue allows authenticated mail users, under specific circumstances, to add files with unsanitized content in public folders where the IIS user had permission to access. This could lead an attacker to store arbitrary code on those files and execute Remote Code Execution (RCE) commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-42136

Affected Products

Mailenable